mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-10-01 14:04:54 +02:00
Make changes based on the view (mostly name clarification).
This commit is contained in:
@@ -37,7 +37,7 @@ from volatility.framework import constants, exceptions, interfaces, layers
|
||||
from volatility.framework.configuration import requirements
|
||||
from volatility.framework.layers import intel, scanners
|
||||
from volatility.framework.symbols import intermed, native
|
||||
from volatility.framework.symbols.windows import mspdb
|
||||
from volatility.framework.symbols.windows import pdbconv
|
||||
|
||||
if __name__ == "__main__":
|
||||
import sys
|
||||
@@ -252,12 +252,12 @@ class KernelPDBScanner(interfaces.automagic.AutomagicInterface):
|
||||
data_written = False
|
||||
with lzma.open(potential_output_filename, "w") as of:
|
||||
# Once we haven't thrown an error, do the computation
|
||||
filename = mspdb.PdbRetreiver().retreive_pdb(
|
||||
filename = pdbconv.PdbRetreiver().retreive_pdb(
|
||||
guid + str(age), file_name = pdb_name, progress_callback = progress_callback)
|
||||
if filename:
|
||||
tmp_files.append(filename)
|
||||
location = "file:" + request.pathname2url(tmp_files[-1])
|
||||
json_output = mspdb.PdbReader(self.context, location, progress_callback).get_json()
|
||||
json_output = pdbconv.PdbReader(self.context, location, progress_callback).get_json()
|
||||
of.write(bytes(json.dumps(json_output, indent = 2, sort_keys = True), 'utf-8'))
|
||||
# After we've successfully written it out, record the fact so we don't clear it out
|
||||
data_written = True
|
||||
|
||||
@@ -26,7 +26,7 @@ from volatility.framework.objects import utility
|
||||
from volatility.framework.symbols import intermed
|
||||
|
||||
|
||||
class PdbMSF(interfaces.layers.TranslationLayerInterface):
|
||||
class PdbMultiStreamFormat(interfaces.layers.TranslationLayerInterface):
|
||||
_headers = {
|
||||
"MSF_HDR": "Microsoft C/C++ program database 2.00\r\n\x1a\x4a\x47",
|
||||
"BIG_MSF_HDR": "Microsoft C/C++ MSF 7.00\r\n\x1a\x44\x53",
|
||||
@@ -40,7 +40,7 @@ class PdbMSF(interfaces.layers.TranslationLayerInterface):
|
||||
super().__init__(context, config_path, name, metadata)
|
||||
self._base_layer = self.config["base_layer"]
|
||||
|
||||
self._pdb_symbol_table = intermed.IntermediateSymbolTable.create(context, self._config_path, 'windows', 'mspdb')
|
||||
self._pdb_symbol_table = intermed.IntermediateSymbolTable.create(context, self._config_path, 'windows', 'pdb')
|
||||
response = self._check_header()
|
||||
if response is None:
|
||||
raise ValueError("Could not find a suitable header")
|
||||
@@ -171,13 +171,13 @@ class PdbMSFStream(interfaces.layers.TranslationLayerInterface):
|
||||
self._pages_len = len(self._pages)
|
||||
if not self._pages:
|
||||
raise ValueError("Invalid/no pages specified")
|
||||
if not isinstance(self._pdb_layer, PdbMSF):
|
||||
raise TypeError("Base Layer must be a PdbMSF layer")
|
||||
if not isinstance(self._pdb_layer, PdbMultiStreamFormat):
|
||||
raise TypeError("Base Layer must be a PdbMultiStreamFormat layer")
|
||||
|
||||
@property
|
||||
def pdb_symbol_table(self) -> Optional[str]:
|
||||
layer = self._context.layers[self._base_layer]
|
||||
if isinstance(layer, PdbMSF):
|
||||
if isinstance(layer, PdbMultiStreamFormat):
|
||||
return layer.pdb_symbol_table
|
||||
else:
|
||||
return None
|
||||
@@ -222,10 +222,10 @@ class PdbMSFStream(interfaces.layers.TranslationLayerInterface):
|
||||
return self.config.get('maximum_size', len(self._pages) * self._pdb_layer.page_size)
|
||||
|
||||
@property
|
||||
def _pdb_layer(self) -> PdbMSF:
|
||||
def _pdb_layer(self) -> PdbMultiStreamFormat:
|
||||
if self._base_layer not in self._context.layers:
|
||||
raise ValueError("No PdbMSF layer found: {}".format(self._base_layer))
|
||||
raise ValueError("No PdbMultiStreamFormat layer found: {}".format(self._base_layer))
|
||||
result = self._context.layers[self._base_layer]
|
||||
if isinstance(result, PdbMSF):
|
||||
if isinstance(result, PdbMultiStreamFormat):
|
||||
return result
|
||||
raise ValueError("Base layer is not PdbMSF")
|
||||
raise ValueError("Base layer is not PdbMultiStreamFormat")
|
||||
|
||||
+2
-2
@@ -17,7 +17,6 @@
|
||||
# WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License for the
|
||||
# specific language governing rights and limitations under the License.
|
||||
#
|
||||
import argparse
|
||||
import binascii
|
||||
import datetime
|
||||
import json
|
||||
@@ -323,7 +322,7 @@ class PdbReader:
|
||||
msf_layer_name = context.layers.free_layer_name("MSFLayer")
|
||||
msf_config_path = interfaces.configuration.path_join("pdbreader", msf_layer_name)
|
||||
new_context.config[interfaces.configuration.path_join(msf_config_path, "base_layer")] = physical_layer_name
|
||||
msf_layer = msf.PdbMSF(new_context, msf_config_path, msf_layer_name)
|
||||
msf_layer = msf.PdbMultiStreamFormat(new_context, msf_config_path, msf_layer_name)
|
||||
new_context.add_layer(msf_layer)
|
||||
|
||||
msf_layer.read_streams()
|
||||
@@ -922,6 +921,7 @@ class PdbRetreiver:
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
import argparse
|
||||
|
||||
class PrintedProgress(object):
|
||||
"""A progress handler that prints the progress value and the description onto the command line"""
|
||||
Reference in New Issue
Block a user